As cited
Copy frozen at (site build).
threat intel
ACR Stealer: Two observed intrusion chains amid increased threat activity
Microsoft Defender Experts observed increased ACR Stealer activity from late April 2026 to mid-June 2026, identifying two distinct intrusion campaigns that use ClickFix social engineering to deliver information-stealing malware. Campaign 1 employs WebDAV-based payload delivery with Python loaders and blockchain-backed command-and-control, while Campaign 2 uses MSHTA and steganography for fileless execution. Both ultimately target browser credentials, authentication tokens, and sensitive enterprise documents.
Why it matters: Enterprise security teams need to detect and block ACR Stealer campaigns now; successful compromise exposes browser credentials and session tokens that enable account takeover, unauthorized cloud access, and further intrusion activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
ACR Stealer: Two observed intrusion chains amid increased threat activity
Microsoft Defender Experts observed increased ACR Stealer activity from late April 2026 to mid-June 2026, identifying two distinct intrusion campaigns that use ClickFix social engineering to deliver information-stealing malware. Campaign 1 employs WebDAV-based payload delivery with Python loaders and blockchain-backed command-and-control, while Campaign 2 uses MSHTA and steganography for fileless execution. Both ultimately target browser credentials, authentication tokens, and sensitive enterprise documents.
Why it matters: Enterprise security teams need to detect and block ACR Stealer campaigns now; successful compromise exposes browser credentials and session tokens that enable account takeover, unauthorized cloud access, and further intrusion activity.
- Source published
- First seen by Cybersecurity Tracker